API reference

    Webhooks: post.published and post.failed

    A Preflight webhook is an https address the workspace subscribes to the events post.published and post.failed. Each delivery is a signed JSON POST — HMAC-SHA256 over the timestamp and the raw body — that says which target of which post went live, with its link, or stopped being retried, with its error. Anything but a 2xx within 10 seconds is retried five times.

    Webhooks

    GET/v1/workspace/webhooksSubscriptions
    POST/v1/workspace/webhooksSubscribe
    DELETE/v1/workspace/webhooks/{id}Unsubscribe
    POST /v1/workspace/webhooks
    { "url": "https://example.com/hooks/preflight", "events": ["post.published", "post.failed"] }
    
    → 201 { "id": "…", "url": "…", "events": [ … ], "secret": "whsec_…" }

    The address must be https and public. The secret is shown once. Events are post.published — once per target, when it is live — and post.failed, sent only once retrying has stopped, so it does not report something that fixes itself.

    POST https://example.com/hooks/preflight
    x-schedulr-event: post.published
    x-schedulr-id: 3f1c…
    x-schedulr-timestamp: 1791300000
    x-schedulr-signature-v2: t=1791300000,v2=9a4e…
    x-schedulr-signature: sha256=5f0c…
    
    { "id": "3f1c…", "event": "post.published", "createdAt": "…",
      "data": { "postId": "…", "targetId": "…", "platform": "tiktok",
            "remoteId": "…", "remoteUrl": "https://www.tiktok.com/@…/video/…" } }
    
    { "id": "…", "event": "post.failed", "createdAt": "…",
      "data": { "postId": "…", "targetId": "…", "platform": "instagram",
            "error": "…", "permanent": true, "attempts": 5 } }

    Verify x-schedulr-signature-v2: take t from the header, compute the hex HMAC-SHA256 of `${t}.${body}` with your secret over the raw request bytes, compare it to v2, and refuse the request when t is more than five minutes from now. That stops a captured request being replayed later. id is the same on every retry of one event, so keep the ids you have handled and ignore a repeat. x-schedulr-signature is the older form — the HMAC of the body alone — kept for receivers written against it; new receivers should check the timed one. Re-encoding the JSON before signing produces a signature that will never match. Answer with a 2xx within 10 seconds; anything else is retried five times with growing gaps. remoteUrl can be null when a network never reports its link.

    Questions: info@preflight.social. The same API as a schema: openapi.json (OpenAPI 3.1).

    Write it once. Let the rules be our problem.

    Preflight checks every post against each network's rules before it leaves, then publishes it to twelve networks. Free plan, no card.